Windows XP全盘加密 – 有哪些选择?

我一直被要求为我们的移动用户查看全盘加密软件.我们在域上运行 Windows XP SP3 PC,我的理解是我们不会升级到Vista并且目前没有计划升级到Windows 7.这似乎排除了Bitlocker.我们想看看两种不同类型的解决方案:

> Active Directory集成的解决方案,可以同步域帐户和密码,以便单点登录到PC.如果可以将解密/加密磁盘访问权限委派给帮助台上的非域管理员,则此解决方案应允许Domain Admins访问任何加密驱动器并获得奖励积分.
>单独或以某种工作组模式在每台PC上运行的解决方案,允许使用单个主密码来解密笔记本电脑的驱动器.对于最终用户单点登录,与域用户帐户和密码同步也很不错.

解决方案必须可靠(例如,当用户被迫在路上更改其域密码时,不会丢失密码同步.)这是一个小商店,因此易于管理很重要.

由于最近的安全漏洞,这些权力可能会排除TrueCrypt,但出于问题的目的,我想听听它是否满足这些要求. BitLocker也是如此 – 由于缺乏升级Windows的愿望,可能会排除它,但我对它在Vista / Windows 7上的工作感兴趣.

为什么,TrueCrypt

Encrypts an entire partition or storage device such as USB flash drive or hard drive.

Using TrueCrypt Without Administrator Privileges

In Windows,a user who does not have administrator privileges can use TrueCrypt,but only after a system administrator installs TrueCrypt on the system. The reason for that is that TrueCrypt needs a device driver to provide transparent on-the-fly encryption/decryption,and users without administrator privileges cannot install/start device drivers in Windows.

After a system administrator installs TrueCrypt on the system,users without administrator privileges will be able to run TrueCrypt,mount/dismount any type of TrueCrypt volume,load/save data from/to it,and create file-hosted TrueCrypt volumes on the system. However,users without administrator privileges cannot encrypt/format partitions,cannot create NTFS volumes,cannot install/uninstall TrueCrypt,cannot change passwords/keyfiles for TrueCrypt partitions/devices,cannot backup/restore headers of TrueCrypt partitions/devices,and they cannot run TrueCrypt in portable mode.

.

07002,which means that anyone who wants to gain access and use the encrypted system,read and write files stored on the system drive,etc.,will need to enter the correct password each time before Windows boots (starts). Pre-boot authentication is handled by the TrueCrypt Boot Loader,which resides in the first track of the boot drive and on the TrueCrypt Rescue disk.

域访问是在引导前登录之后.

但是,如果用户需要更改密码并且雇主希望知道该密码,则是雇主信任用户/雇员的问题.

相关文章

Windows2012R2备用域控搭建 前置操作 域控主域控的主dns:自...
主域控角色迁移和夺取(转载) 转载自:http://yupeizhi.blo...
Windows2012R2 NTP时间同步 Windows2012R2里没有了internet时...
Windows注册表操作基础代码 Windows下对注册表进行操作使用的...
黑客常用WinAPI函数整理之前的博客写了很多关于Windows编程的...
一个简单的Windows Socket可复用框架说起网络编程,无非是建...